Live data from Hacker News

It's Time to Break Up the NSA (2014)

schneier.com

71–80 of 140 posts

Re: It's Time to Break Up the NSA (2014)

#71

Read "The Puzzle Palace" and find out why the NSA is structured like it is. The US gov has been re-orging the NSA and factions inside the gov have been fighting over its control since its inception. To use an annoyingly beat to death phrase: we haven't seen its final form yet. Actually a pretty good article overall, but these two lines bother me greatly: > "What was supposed to be a single agency with a dual mission—…

Never mind that "security" is literally their middle name--the second L of their TLA. It wouldn't be the first time that a government enterprise had a misleading name.

Exactly. They have as much to do with "security" as the Democratic People's Republic of Korea has to do with "democracy."

Re: It's Time to Break Up the NSA (2014)

#72

I don't understand why society thinks that certain things can be contained, while certain other things cannot be. The liberals will always be telling you that the drug war is a failure, and that drug users will be able to get their hands on drugs anyway, and we should embrace that fact so we can retain some level of control, and so otherwise innocent people don't have to interact with criminals. But guns on the other…

1- tor is broken. 2- they know and use ways to get around encrypting. We got to give them some credit they knew encryption was an issue that at some point they had to dealt with. And they found ways to do just that from the beginning.

Re: It's Time to Break Up the NSA (2014)

#73
post #72

I don't understand why society thinks that certain things can be contained, while certain other things cannot be. The liberals will always be telling you that the drug war is a failure, and that drug users will be able to get their hands on drugs anyway, and we should embrace that fact so we can retain some level of control, and so otherwise innocent people don't have to interact with criminals. But guns on the other…

1- tor is broken. 2- they know and use ways to get around encrypting. We got to give them some credit they knew encryption was an issue that at some point they had to dealt with. And they found ways to do just that from the beginning.

they don't even need to break encryption. Patriot Act.

Re: It's Time to Break Up the NSA (2014)

#74

It just seems that you can do anything on paper but covert agreements between the agencies after break up will still occur.

Defund them, it's not perfect (as with the CIA and it's ah interesting funding mechanisms) but it is one of the more effective of the least worst options.

Re: It's Time to Break Up the NSA (2014)

#75
post #59

Earlier quoted context omitted.

There's a distinction to be drawn between James Bond-style spying ("Humint" - which is the kind you're actually referring to) and the large-scale, indiscriminate, archived, mass-surveillence of otherwise ordinary people ("Sigint" - which is what we've learned about over the last couple of years).

Sigint has been around signals signals were around. The only reason I see a reason to distinguish is what the info collected is being used to so America can blackmail German citizens, that is shitty. But if we are just trying to collect information about Germany or people who just happen to be in German who are people of interest? That is the NSA mission. The real issue is the potential for abuse. But the US governme…

> "... who are people of interest?"

I think you've missed the part where everyone is now (effectively) a person of interest.

Re: It's Time to Break Up the NSA (2014)

#76

I don't understand why society thinks that certain things can be contained, while certain other things cannot be. The liberals will always be telling you that the drug war is a failure, and that drug users will be able to get their hands on drugs anyway, and we should embrace that fact so we can retain some level of control, and so otherwise innocent people don't have to interact with criminals. But guns on the other…

Encryption is orthogonal to policy, which is the topic of the article.

Re: It's Time to Break Up the NSA (2014)

#77
post #75

Earlier quoted context omitted.

Sigint has been around signals signals were around. The only reason I see a reason to distinguish is what the info collected is being used to so America can blackmail German citizens, that is shitty. But if we are just trying to collect information about Germany or people who just happen to be in German who are people of interest? That is the NSA mission. The real issue is the potential for abuse. But the US governme…

> "... who are people of interest?" I think you've missed the part where everyone is now (effectively) a person of interest.

That is just not true. Sure, they are collecting some limited information on every, but mostly because its harder to collect targeted information than to just get it all.

So maybe the US has a record of every call made in Germany, but nobody is tracking some random bus driver in Bavaria.

Right now there aren't is the manpower to actually look at even a tiny fraction of what is collected.

I guess in the future, if an AI with human like ability is created, the actual monitoring of every person could occur. But it just isn't a fear right now.

I'd call it psuedo-pirvacy.

Re: It's Time to Break Up the NSA (2014)

#78
post #3

I think an even better argument for breaking up the NSA is that there's a fourth category of work they (should) do that's totally unrelated to surveillance and that I'd classify as "very good:" actively working to secure the communications of US government and companies against the NSA-equivalents of other nation-states and rogue actors. Having this is on the same list as encryption sabotage is a recipe for mismanage…

The NSA's Information Assurance wing considers itself responsible for the security of classified US Government systems only—specifically not unclassified US Government systems, or any civilian systems whatsoever, which they feel falls under NIST's domain.

But yes, it's much smaller than their SIGINT wing, and yes, I also feel that having both teams under the same roof (so to speak) is not just an 'equities problem' - it's a full-scale irreconcilable conflict of interest.

You might feel that surely the NSA wouldn't backdoor their own stuff? But no: there they are, actually using Dual_EC_DRBG even in their own most trusted crypto hardware - in, I presume, the firm belief that "nobody but us" has the private key to use the backdoor. Which seems somewhat reckless in light of a working distinguisher and how very fragile (EC)DSA is… and a stark reminder of how the recent return to talk of backdoors - sorry, "front doors" or "secure golden keys", because they want to control the language to frame the debate in the way they want - are so much bullshit, and the only reasonable discussion we can have about things which undermine all of our collective security is one where the people who are asking for such idiotic things to - they think - make their jobs easier should kindly shut the fuck up.

Ahem.

GCHQ over here have the exact same issue with CESG and the MoD CRYPTO group versus the COMINT/ELINT/SIGINT bulk of their mission. GCHQ have even selected their own suppliers and political and other infrastructure for targeted surveillance in some cases! So for those who choose to try to work with them - surprise! - that doesn't mean they're not also working against you too. It just gives them another angle.

Re: It's Time to Break Up the NSA (2014)

#79
post #17

Bruce makes a good point here. There is a balance between the COMSEC and SIGINT. Any advance you make in SIGINT is a failure of COMSEC and vice versa. The issue is then the 'viruses' of our internet ecosystem, the hackers and state level threats. How do you balance the two? Will the nature of the system self-balance as threats are discovered and then bandaged? Still, good job not just demonizing the NSA, they serve a…

It seems to be a sort of universal truth in that the people trying to break a system will always be ahead of people trying to secure/protect it. Why then, would prioritizing COMSEC over SIGINT change any of that? COMSEC will never catch up to SIGINT.

I'm curious to know what exactly the NSA currently does to protect the US. Do they already use their existing SIGINT knowledge to update systems ahead of attacks?

Re: It's Time to Break Up the NSA (2014)

#80
post #18

I'm thankful to live in a country where we have the freedom to publish this kind of thing. (That said, I think that freedom will no last too much longer.)

I've got an idea. In the faux name of net neutrality, let's give one of the most abusive governments when it comes to privacy, vast control over regulating the domestic Internet, and let's allow them pass those new regulations without anyone external being allowed to review them ahead of time. What could possibly go wrong? It's not like the government will massively expand their direct control of the Internet, and us…

I agree with the general thrust of what you're saying, and I think the FCC takeover of the internet is much more problematic than the NSA spying scandal.

That said, the EFF is getting what it has been advocating for: A government takeover of the internet.

That is what net neutrality has always been for and about.

Once we grant that the internet infrastructure is not private property and is open to government regulation, that means it's open to all government regulation, including speech regulation. There is no middle ground.

To think otherwise is to not understand principles and politics.

Post reply on HN